Prompt
How do I revoke access tokens when users disconnect an app?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
To revoke access tokens when a user disconnects an app, you generally need to:
-
Delete the app’s stored credentials on your side
- Remove the user’s access token, refresh token, and any session records from your database.
- Mark the app connection as disconnected so you stop making API calls on the user’s behalf.
-
Call the provider’s token revocation endpoint, if available
- Many OAuth providers support revoking tokens explicitly.
- Usually you send the access token and/or refresh token to a revocation endpoint.
- Revoking the refresh token is especially important because it prevents new access tokens from being minted.
-
Handle both access and refresh tokens
- If the provider issues short-lived access tokens, they may expire quickly anyway.
- If there is a refresh token, revoke that too, because it can keep the connection alive.
-
If no revocation endpoint exists
- Invalidate the token connection in your app’s database.
- Rely on token expiration.
- If you control the authorization server, implement server-side token invalidation.
-
Make sure disconnect is idempotent
- If the user clicks disconnect twice, your app should safely handle it without errors.
Example flow
When the user disconnects:
- User clicks “Disconnect”
- Your backend:
- finds the saved tokens
- calls provider revocation endpoint
- deletes tokens from your database
- removes any related refresh grant/session
- Return success to the user
Important notes
- Some providers revoke all tokens tied to a grant when you revoke one token, while others revoke only the specific token.
- For security, always revoke refresh tokens first if possible.
- If the token is stored client-side, you should still clear it from the client, but real revocation must happen server-side.
If you want, I can show you:
- a generic OAuth revocation example
- examples for Google, GitHub, Microsoft, Slack, or Salesforce
- or a sample backend implementation in Node.js, Python, or PHP.